CVE-2026-65919
HIGHMeshery < 1.0.57 Unauthenticated Arbitrary File Read via fileView and fileDownload
Title source: cnaDescription
Meshery before 1.0.57 contains an unauthenticated arbitrary file read vulnerability in the /api/system/fileView and /api/system/fileDownload endpoints that pass user-supplied file parameters directly to os.Open without path validation. Attackers can supply absolute paths or traversal sequences in the file parameter to read arbitrary files from the host filesystem without authentication.
References (5)
Core 5
Core References
Patch patch
Patch Commit
https://github.com/meshery/meshery/commit/ea83a26cb090b13be36c07cf24a99f8c637cc765
Third Party Advisory third-party-advisory
https://www.vulncheck.com/advisories/meshery-unauthenticated-arbitrary-file-read-via-fileview-and-filedownload
Technical Description technical-description
issue-tracking
Researcher Disclosure
https://github.com/meshery/meshery/issues/20076
Release Notes release-notes
patch
Release Notes
https://github.com/meshery/meshery/releases/tag/v1.0.57
Scores
CVSS v3
7.5
EPSS
0.0061
EPSS Percentile
45.6%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
yes
Technical Impact
partial
Details
CWE
CWE-22
Status
published
Products (1)
meshery/meshery
< 1.0.57
Published
Jul 23, 2026
Tracked Since
Jul 23, 2026